如何在Windows系统搭建独立YubiKey OTP验证服务器?
在Windows系统搭建独立YubiKey OTP验证服务器的完整步骤
我来一步步教你在Windows上搭建独立的YubiKey OTP验证服务器,亲测可行,跟着做就行:
一、准备环境:启用WSL2(推荐方案)
因为官方的YubiKey OTP验证服务器主要基于Linux环境开发,用WSL2在Windows上跑是最稳定且省心的方式:
- 打开PowerShell(管理员权限),运行命令启用WSL和虚拟机平台:
wsl --install - 重启电脑后,按照提示安装Ubuntu(或你熟悉的Linux发行版),设置用户名和密码。
二、安装YubiKey OTP验证服务器
进入WSL的Ubuntu终端,执行以下步骤:
- 添加Yubico官方软件源:
curl -s https://packages.yubico.com/Yubico-GPG-Key.pub | sudo apt-key add - echo "deb https://packages.yubico.com/stable/ubuntu $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/yubico.list - 更新源并安装服务器:
sudo apt update && sudo apt install yubikey-server-otp
三、配置服务器
编辑配置文件:
sudo nano /etc/yubikey-server-otp/config.yaml关键配置项修改:
listen_address: 设置为0.0.0.0:8080(允许Windows主机访问)database: 默认是SQLite路径(/var/lib/yubikey-server-otp/db.sqlite3),小型部署无需修改api_key: 设置一个自定义的密钥(比如my-secret-api-key),用于后续管理设备
按Ctrl+O保存,Ctrl+X退出。
初始化数据库:
sudo yubikey-server-otp init-db这个命令会创建SQLite数据库结构,用于存储YubiKey的凭证信息。
四、设置服务器开机自启
用systemd把服务器配置成服务,避免每次重启WSL都手动启动:
- 创建服务文件:
粘贴以下内容:sudo nano /etc/systemd/system/yubikey-otp-server.service[Unit] Description=YubiKey OTP Validation Server After=network.target [Service] ExecStart=/usr/bin/yubikey-server-otp serve Restart=always User=root [Install] WantedBy=multi-user.target - 启用并启动服务:
可以用sudo systemctl daemon-reload sudo systemctl enable --now yubikey-otp-serversystemctl status yubikey-otp-server检查服务是否正常运行。
五、导入你的YubiKey设备
需要把YubiKey的凭证信息导入服务器,这样服务器才能验证该设备的OTP:
- 在Windows上安装YubiKey Manager(直接从官方渠道下载安装即可)
- 插入YubiKey,打开YubiKey Manager:
- 切换到「OTP」标签页,点击「配置Slot 1」(或你常用的Slot)
- 记录下Public ID(比如
cccccccccccc,是OTP码的前缀部分) - 点击「导出Secret Key」,选择Base64格式,复制密钥内容
- 回到WSL终端,执行导入命令:
替换尖括号里的内容即可。sudo yubikey-server-otp add-credential --public-id <你的Public ID> --secret-key <复制的Base64密钥>
六、测试OTP验证
在Windows的PowerShell里发送请求测试:
- 按下YubiKey的按钮,复制生成的完整OTP码(比如
ccccccccccccabcdefghijklmnopqrstuv) - 执行命令:
如果返回Invoke-RestMethod -Uri "http://localhost:8080/verify?otp=<你的完整OTP码>"{"status": "OK"},说明验证成功!如果返回{"status": "BAD_OTP"},检查OTP码是否正确或设备是否导入成功。
七、可选优化
- 防火墙设置:如果Windows防火墙拦截了8080端口,需要在「Windows Defender防火墙」里添加允许8080端口的入站规则
- HTTPS配置:如果需要在公网使用,可以用Let's Encrypt给WSL里的服务器配置HTTPS证书,修改配置文件里的
tls_cert和tls_key路径 - 集成到应用:你的应用可以通过调用
/verify接口来完成OTP验证,请求参数就是otp,返回的JSON里的status字段判断是否验证通过
内容的提问来源于stack exchange,提问作者user213
相关产品推荐
相关产品推荐

